ExamGecko
Question list
Search
Search

Question 521 - CISM discussion

Report
Export

Which of the following should be the FIRST step in patch management procedures when receiving an emergency security patch?

A.
Schedule patching based on the criticality.
Answers
A.
Schedule patching based on the criticality.
B.
Install the patch immediately to eliminate the vulnerability.
Answers
B.
Install the patch immediately to eliminate the vulnerability.
C.
Conduct comprehensive testing of the patch.
Answers
C.
Conduct comprehensive testing of the patch.
D.
Validate the authenticity of the patch.
Answers
D.
Validate the authenticity of the patch.
Suggested answer: D

Explanation:

Validating the authenticity of the patch is the first step in patch management procedures when receiving an emergency security patch, as it helps to ensure that the patch is genuine and not malicious. Validating the authenticity of the patch can be done by verifying the source, signature, checksum, or certificate of the patch, and comparing it with the information provided by the software vendor or manufacturer. Installing an unverified patch may introduce malware, compromise the system, or cause unexpected errors or conflicts.

Reference= CISM Review Manual 2022, page 3131; CISM Exam Content Outline, Domain 4, Task 4.42; Practical Patch Management and Mitigation1; Vulnerability and patch management in the CISSP exam3

asked 01/10/2024
Joseph Bauer
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first